Back

CSBS Releases AI Supervisory Framework for State Examiners

At a glance

  • The CSBS published an AI Supervisory Framework on September 16, 2026.
  • The framework is a voluntary tool for state examiners and does not create new legal requirements.
  • It includes guides, work programs, and supplements to address AI risks in financial institutions.

The Conference of State Bank Supervisors (CSBS) has introduced a new Artificial Intelligence Supervisory Framework to assist state examiners in evaluating AI-related practices at state-chartered banks and nonbank financial institutions. This development provides a structured approach for regulators to address the use and risks of AI technologies in the financial sector.

The framework, released on September 16, 2026, is intended as a discretionary resource rather than a mandatory regulation. According to the CSBS, it does not impose new substantive legal obligations on financial institutions but serves as a reference for examiners during supervisory activities.

Designed to be adaptable, the framework considers factors such as each institution’s size, complexity, risk profile, and specific applications of artificial intelligence. This approach enables examiners to tailor their assessments based on the characteristics and risk exposures of individual banks and nonbank entities.

The framework incorporates guidance from several established sources, including the National Institute of Standards and Technology’s AI Risk Management Framework, the Cyber Risk Institute’s Financial Services AI Risk Management Framework, and the U.S. Department of the Treasury’s AI Lexicon. These resources provide foundational risk management concepts and terminology relevant to financial services.

What the numbers show

  • The framework was published on September 16, 2026.
  • It applies to state-chartered banks and state-licensed nonbank financial institutions.
  • Each state agency decides how to use the framework in its programs.

Several components make up the framework, including a Core Examiner Guide that features scoping questions and document request lists, an Examiner Work Program, and Nonbank AI Supplements that address risks related to third parties, models, and consumer protection. There is also an optional worksheet for risk tiering of AI use cases, which examiners can use to determine the level of review needed.

The framework is structured to help examiners identify where AI is used within an institution, assess related risks, and decide when a more detailed examination may be necessary. This process aims to support consistent supervisory practices across different types of financial institutions.

Financial institutions are provided with clearer expectations regarding how examiners may review AI systems, including generative AI technologies that are not specifically addressed by existing federal model-risk guidance. This clarity is intended to support both examiners and institutions in navigating evolving AI applications.

According to the CSBS, each state financial regulatory agency will independently determine the extent to which it incorporates the framework into its supervisory processes. This allows for flexibility and adaptation to the unique regulatory environments of individual states.

* This article is based on publicly available information at the time of writing.